The new iPhone security story sounds terrifying at first: seven iPhone models are affected by a hardware vulnerability that cannot be fully removed by a software update, and even iOS 27 cannot make it disappear.
That is true in the narrow technical sense. It is also the kind of sentence that needs careful handling.
The vulnerability is called usbliter8. It was disclosed by security research firm Paradigm Shift on June 18, 2026, and it targets Apple’s BootROM, also called SecureROM, on A12 and A13-era chips. Mobilissimo covered the Romanian reader-facing version of the story, correctly noting that the affected iPhone list includes the iPhone XS, XS Max, XR, iPhone 11, 11 Pro, 11 Pro Max, and iPhone SE 2.
The practical version is calmer: this is a serious hardware-rooted exploit for researchers, jailbreak developers, device-forensics teams, and high-security environments. It is not a web link, rogue app, or remote attack that suddenly compromises an ordinary iPhone from across the internet.
What usbliter8 actually is
BootROM is the very first code a device runs when it starts. Because it is burned into the chip, a flaw at that level is different from a normal iOS bug. Apple can update iOS, firmware, apps, WebKit, and plenty of other software layers. It cannot rewrite silicon that shipped years ago.
Paradigm Shift says usbliter8 combines a hardware bug in the USB controller with a firmware configuration issue. In simplified terms, carefully shaped USB packets can push writes into memory areas that should not be writable during the early boot process. From there, the researchers demonstrated code execution inside the SecureROM path on affected chips.
That is why this is being compared to checkm8, the famous 2019 BootROM exploit that permanently affected older iPhones up to the iPhone X generation.
The affected iPhones
For phone buyers, the headline list is short and important.
| iPhone model | Chip | iOS 27 status |
|---|---|---|
| iPhone XS | A12 Bionic | Not listed for iOS 27 by Apple |
| iPhone XS Max | A12 Bionic | Not listed for iOS 27 by Apple |
| iPhone XR | A12 Bionic | Not listed for iOS 27 by Apple |
| iPhone 11 | A13 Bionic | Listed for iOS 27 |
| iPhone 11 Pro | A13 Bionic | Listed for iOS 27 |
| iPhone 11 Pro Max | A13 Bionic | Listed for iOS 27 |
| iPhone SE, 2nd generation | A13 Bionic | Listed for iOS 27 |
The broader research is not limited to iPhones. Paradigm Shift also lists A12, S4/S5, and A13 SoCs as supported by the public proof of concept, which brings some iPads and Apple Watches into the broader hardware conversation. But the seven-iPhone framing is useful because those are the devices most readers are likely to have in a drawer, hand down to family, or buy refurbished.
Why iOS 27 cannot fully fix it
Apple’s iOS 27 compatibility page lists the iPhone 11 series and iPhone SE 2. That means those A13 phones are still getting the next big iOS generation.
But support is not the same as a silicon fix.
Apple can add mitigations, reduce exposure, improve lockdown behavior, and patch surrounding software. What it cannot do is replace the BootROM design inside an A12 or A13 chip already soldered into a phone. Paradigm Shift makes the same point directly: newer hardware is the most effective mitigation for this class of issue.
This is the difference between “Apple can still make the phone safer” and “Apple can delete the bug.” The first is possible. The second is not.
The risk is real, but physical
The important limit is physical access.
This exploit is not triggered by visiting a website. It does not arrive through iMessage. It is not an App Store malware story. Reporting from The Hacker News and other security outlets describes the public exploit path as requiring the device to be connected over USB in DFU mode with specialized hardware.
That changes the risk model completely.
| User type | What this means |
|---|---|
| Normal users | Keep updating iOS and do not panic. The practical risk is low without physical access. |
| Refurbished-phone buyers | Prefer newer A14-or-later devices if long-term security matters. |
| Journalists, activists, executives | Treat A12/A13 devices as higher-risk if they can leave your control. |
| Companies and government teams | Inventory A12/A13 devices and decide whether sensitive roles need newer hardware. |
| Jailbreak/research users | This is historically significant because it extends public BootROM exploitation beyond the iPhone X era. |
The risk becomes more serious when someone can take the device, connect it to hardware, put it into DFU mode, and work on it outside the owner’s control.
What about the Secure Enclave?
This part matters because panic headlines can imply that all user data is automatically exposed. Paradigm Shift does not claim that usbliter8 directly compromises the Secure Enclave.
Apple’s own Platform Security documentation describes the Secure Enclave as an isolated subsystem designed to protect sensitive data even if the main application processor is compromised. Paradigm Shift’s conclusion is more nuanced: BootROM-level control can open broader paths to attack the Secure Enclave, but that is not the same as saying passcodes, Face ID data, or keys are instantly defeated.
In other words, this lowers the ground under the device’s boot chain. It does not magically hand every attacker your secrets.
What users should actually do
If you own one of these iPhones, the advice depends on your threat model.
- Keep installing Apple security updates. They still matter for the parts of the system Apple can patch.
- Use a strong passcode, not a short 4-digit code.
- Do not leave the device unlocked or unattended with untrusted people.
- Avoid using unknown USB accessories, cables, repair rigs, or charging stations.
- If the phone is used for sensitive work, consider replacing it with an A14-or-newer iPhone.
- If buying refurbished, treat the iPhone 12 generation and newer as the safer long-term baseline.
- If the device is a child phone, backup phone, music player, or casual spare, the exploit alone is not a reason to panic-recycle it.
The hardware line matters because Paradigm Shift says A14 and later configure the relevant memory protection differently enough that this particular exploit path is not viable.
Bottom line
usbliter8 is a real and important iPhone security milestone. It shows that even relatively modern Apple hardware can carry BootROM-level surprises that software updates cannot fully remove.
But the consumer takeaway should be precise, not dramatic. The affected iPhones are not suddenly unsafe to browse the web with. This is a physical-access, early-boot exploit. For most people, regular updates and basic device custody are still the right answer.
For high-risk users, companies, and anyone buying refurbished hardware for long-term use, the answer is different: A12 and A13 devices now have a permanent asterisk. iOS 27 can keep an iPhone 11 useful. It cannot make that chip new.
Support independent tech explainers at buymeacoffee.com/gearpulse.site.